Skip to main content
Trust dossier

How we handle your data.

Our customers run plants, pipelines, and other critical infrastructure, and they hold their own systems to a high bar. We hold the platform to the same one. The public posture is below: US data residency, no customer data in model training, SOC 2 Type II in progress, role-based access, and single sign-on (SSO) on Enterprise.

We share the sub-processor list and penetration-test letter under a non-disclosure agreement (NDA) on request. Our standard Data Processing Agreement (DPA) is being finalized, with an interim addendum available in the meantime.

Residency
US regions only
Model training
No customer data
Encryption
TLS 1.3 / AES-256
SOC 2 Type II
In progress, Q4 2026

The commitment schedule

Residency

Data residency

All customer data (queries, chats, LOI drafts, billing records) is stored in US-based regions, with US-based disaster recovery. No data leaves the United States. EU residency is available on Enterprise upon request.

In place
Training

No customer data used for model training

We never use your queries, chats, or uploaded content to train or fine-tune models, and our model providers do not train on data sent through their APIs. This is contractual.

In place
Encryption

Encryption

In transit: TLS 1.3 everywhere, HSTS enforced. At rest: AES-256 across the database, document store, and search index. Database backups encrypted with separate keys.

In place
Access

Access control

Role-based access (Owner / Admin / Member) at the org tenancy level, available on every plan. Enterprise tier adds single sign-on (SSO) via SAML 2.0 (Okta, Azure AD, Google Workspace). SCIM 2.0 user provisioning and workspace IP allow-listing are on the Enterprise roadmap. They are not yet generally available, so ask us about timelines if they gate your purchase.

Audit log

Audit logging

We write account-level events to an append-only audit log: sign-in, member and role changes, organization and SSO provisioning, and billing actions. Each entry captures the target, a timestamp, and the acting user where the action carries one. Expanded coverage (chat access and Letter of Interpretation (LOI) export events, Admin-facing export, and SIEM streaming to Splunk, Datadog, and Elastic) is in active development for Enterprise. We will not represent it as shipped until it is. Talk to us if audit export is a requirement.

Sub-proc

Sub-processors

Cairn relies on a small set of US-based sub-processors covering model inference, managed database, search infrastructure, object storage, and billing. The named list and notification policy are available on request. Our standard DPA is being finalized; an interim data-protection addendum is available for customers who need to sign before it ships.

Compliance

Compliance

SOC 2 Type II audit in progress (Q4 2026). HIPAA BAA available on Enterprise. CJIS, FedRAMP, and ITAR not currently supported.

In progress
Disclosure

Vulnerability disclosure

We operate a private security disclosure program. Email security@cairnsafe.com with PGP-encrypted reports. We respond within one business day and run a 90-day disclosure timeline by default.

In place
AI safety

AI safety posture

Cairn is designed to refuse to fabricate. We ground assistant responses in retrieved citations or mark them as model-generated. We monitor citation hit rate, refusal rate, and prompt-injection attempts, and we review the findings weekly.

In place

For a procurement review, see plans and pricing, who builds Cairn, or talk to sales about a security questionnaire.

We keep pre-filled CAIQ and SIG Lite responses ready for your security review.